EU dual-use export control for cryptography and AI refers to the body of law, principally Regulation (EU) 2021/821, that restricts the transfer of encryption technologies, post-quantum cryptographic software and AI model weights across borders on grounds of national security and foreign policy. For European organisations building sovereign infrastructure, this framework creates licensing obligations, residual foreign-jurisdiction risks and procurement constraints that sit alongside, and frequently intersect with, GDPR, NIS-2 and DORA.
What the EU Dual-Use Regulation Actually Controls
Regulation (EU) 2021/821 governs the export, brokering, transit and technical assistance of items listed in its Annex I. For sovereign infrastructure operators, the most immediately relevant entries are Category 5 Part 2 (information security, including cryptographic hardware and software) and Category 4 (computers, including high-performance AI accelerators). The September 2025 updated Annex I Control List aligned these entries more closely with Wassenaar Arrangement plenary decisions from 2023 and 2024, adding clarifications affecting large-model inference hardware and certain AI-accelerator architectures under 5A002 and 4A003 entries.
Post-quantum cryptographic algorithms, as standalone software libraries, generally benefit from the publicly available technology decontrol note in Annex I and the general exception in Article 2(21) of the Regulation, provided the software is published without access restriction. However, once a PQC library is integrated into a commercial product, bundled with proprietary tooling, or transferred to a destination subject to EU restrictive measures, that exception may no longer apply and a formal licence assessment becomes necessary.
AI model weights present a newer and less settled classification question. Current Annex I entries do not explicitly list large language model weights as controlled items, but the hardware required to train or run frontier models at scale, particularly high-performance GPU clusters and specialised AI accelerators, can fall under Category 4 controls. The September 2025 update addressed this ambiguity only partially, leaving a gap that the forthcoming full evaluation of the Regulation is expected to close.
The 2026 to 2028 Evaluation and Its Regulatory Risk Implications
Article 29 of Regulation (EU) 2021/821 mandates a full evaluation of the Regulation between September 2026 and September 2028. The European Commission has signalled that AI model weights, quantum-computing components and cyber-surveillance software are priority topics for that review.
For organisations that have built sovereign infrastructure product roadmaps on the current decontrol exceptions, particularly for open-source AI models such as Mistral and Llama variants, this creates a concrete regulatory risk posture challenge. If the evaluation results in new control entries covering model weights above a certain parameter threshold, transfers that are currently unrestricted would require export licences. Organisations with international clients in regulated sectors should document their current classification assessments now, so that they can demonstrate a defensible compliance position during any transitional period and respond quickly if the Annex I is updated.
The EU Dual-Use Coordination Group, established under Article 24 of the Regulation, coordinates between member state competent authorities and provides guidance on harmonised implementation. Engaging with that group’s public consultation phases, and monitoring its opinions on emerging technology categories, is a practical way to reduce surprise exposure during the evaluation window. According to the European Commission’s 2023 review of the dual-use regulation, over 70 percent of EU member states had not yet fully harmonised their national enforcement of Category 5 Part 2 cryptography controls, meaning that the current compliance landscape is already uneven and will likely tighten as the evaluation conclusions are implemented.
Residual US-Jurisdiction Dependencies: EAR and ITAR Inside EU-Hosted Environments
A common misconception among European IT decision-makers is that hosting infrastructure in the EU eliminates foreign-jurisdiction exposure. This is incorrect when US-origin hardware or software is present in the stack. The US Export Administration Regulations (15 CFR Parts 730 to 774, administered by the Bureau of Industry and Security) impose jurisdiction over items of US origin regardless of their physical location, through the foreign-direct-product rule and the de minimis provisions in 15 CFR Parts 734 and 736.
Practically, this means that an EU-hosted sovereign cloud built on US-manufactured CPUs, US-developed hypervisor software, or US-origin network chipsets may require BIS authorisation before certain re-exports or configuration transfers to third countries. ITAR (22 CFR Parts 120 to 130), administered by the Directorate of Defense Trade Controls, imposes even stricter obligations for defence-related cryptographic items and can restrict the nationality of personnel with access to controlled systems, creating challenges for multi-national IT teams managing sovereign infrastructure.
| Regulatory Regime | Primary Scope for Sovereign Infrastructure | Key Trigger for EU Operators | Residual Risk Even with EU Hosting |
|---|---|---|---|
| Regulation (EU) 2021/821 | Cryptographic software, PQC tools, AI accelerator hardware transferred to non-EU recipients | Transfer to non-EU client or partner; technical assistance to restricted destination | Annex I updates may reclassify currently decontrolled items |
| EAR (15 CFR 730–774) | US-origin hardware and software in the infrastructure stack | Re-export or deemed export of US-origin components or technology | Foreign-direct-product rule applies regardless of hosting location |
| ITAR (22 CFR 120–130) | Defence-related cryptographic items; certain quantum-computing hardware | Personnel nationality restrictions; transfer to foreign nationals | Access controls must account for nationality of system administrators |
Structuring Procurement and Vendor Contracts to Limit Dual-Use Exposure
Regulated organisations can limit dual-use exposure through deliberate contract architecture. Vendor agreements for cryptographic hardware, PQC-capable hardware security modules and AI inference hardware should require the vendor to provide: the Export Control Classification Number (ECCN) for all supplied items, a written confirmation of whether any US-person involvement triggers ITAR jurisdiction, and a binding data-processing agreement ensuring that no personal data leaves the EU in the context of support, maintenance or telemetry.
PQC-capable HSMs sourced from US or Chinese manufacturers create a compounded risk. On the export-control side, they may carry an ECCN of 5A002 or 5E002 and require BIS authorisation for certain uses. On the data-protection side, if the manufacturer or its parent is subject to FISA 702 obligations or the Chinese National Intelligence Law, any remote firmware update or support channel could constitute a restricted international transfer under GDPR Chapter V. A single procurement contract that addresses both dimensions, rather than treating export control and GDPR as separate workstreams, closes this gap most efficiently.
The EU Dual-Use Coordination Group and ENISA Cyber-Surveillance Guidelines
The EU Dual-Use Coordination Group serves as the primary forum for harmonising member state interpretations of Regulation (EU) 2021/821, particularly for emerging technology categories where Annex I entries are ambiguous. For sovereign infrastructure operators, the Group’s opinions on cyber-surveillance tooling are directly relevant: intrusion software, network monitoring platforms and certain AI-powered threat-detection systems can fall under the catch-all controls of Category 4 and Category 5 depending on their capability profile.
ENISA has published cyber-surveillance exporter guidelines that complement the Coordination Group’s work by identifying due-diligence obligations for organisations that supply cybersecurity tooling to third-country clients. These guidelines emphasise end-use verification, post-shipment checks and contractual conditions that prevent re-export to high-risk destinations. As ENISA noted in its post-quantum cryptography guidance: “Cryptographic controls in the dual-use framework were designed for a world of hardware tokens and closed networks. Applying them to open-source PQC libraries and distributed AI model weights requires a fundamental rethink of what ‘export’ means in 2025.”
NIST finalised its first three post-quantum cryptography standards, FIPS 203, FIPS 204 and FIPS 205, in August 2024, providing the technical baseline against which HSM vendors and sovereign infrastructure operators now benchmark PQC capability. The existence of these NIST standards has accelerated HSM vendor roadmaps, which in turn increases the urgency of getting the export-control classification of PQC-capable HSMs resolved before procurement decisions are locked in.
Interaction with GDPR Transfer Restrictions and CLOUD Act Exposure
The intersection of dual-use export controls and GDPR Chapter V restrictions is underappreciated. When quantum-computing hardware or PQC-capable infrastructure components are sourced from US manufacturers, the same transatlantic legal architecture that creates CLOUD Act exposure also affects the export-control compliance picture. A US-headquartered HSM vendor subject to a National Security Letter or FISA 702 production order has no legal basis to notify its EU customer that a government demand has been made. This mirrors the structural exposure that European organisations face when using US-controlled cloud services, but it applies here to the physical security layer of sovereign infrastructure rather than to data-at-rest in a public cloud.
The EU-US Data Privacy Framework, adopted in 2023, reduces but does not eliminate this exposure, particularly for intelligence community access under FISA 702 which operates outside the Framework’s redress mechanism for categories of data classified as national security relevant. Organisations that treat their sovereign infrastructure as a GDPR compliance answer must therefore also account for whether the hardware supply chain itself reintroduces the very foreign-jurisdiction dependency they were trying to eliminate.
The IBM Cost of a Data Breach Report 2023, referenced by ENISA, placed the average cost of a major breach for European organisations in critical sectors at approximately €4.45 million, a figure that does not include regulatory fines or the reputational cost of a compliance failure attributable to an overlooked export-control obligation in the supply chain. For compliance officers and CISOs making the business case for sovereign procurement, that figure provides a concrete financial anchor for the cost of inadequate due diligence.
Frequently Asked Questions
Does open-source PQC software such as liboqs require an export licence under EU dual-use rules?
Open-source cryptographic software that is publicly available without access restrictions benefits from the general exception in Regulation (EU) 2021/821 Article 2(21) and the corresponding decontrol note in Annex I Category 5 Part 2. However, if the software is modified, bundled into a commercial product, or transferred to a sanctioned destination, the exception may not apply and a licence assessment is required.
If a European organisation runs a sovereign cloud on US-manufactured server hardware, does EAR still apply?
Yes. Under the EAR de minimis and foreign-direct-product rules (15 CFR Parts 734 and 736), hardware and software of US origin can remain subject to US jurisdiction regardless of where it is physically located. An EU-hosted environment built on US-origin CPUs, network chipsets or hypervisor software may require BIS authorisation before certain re-exports or transfers to third countries.
What is the September 2025 update to Annex I of Regulation (EU) 2021/821, and why does it matter for AI?
The September 2025 update aligned Annex I more closely with recent Wassenaar Arrangement plenary decisions, adding clarifications to Category 4 (computers) and Category 5 Part 2 (cryptography) that affect large-model inference hardware and certain AI-accelerator architectures. Organisations deploying on-premise AI infrastructure using high-performance accelerators should reassess whether their hardware falls under the updated 5A002 or 4A003 entries before transferring configurations or model weights to non-EU clients.
How does the 2026 to 2028 evaluation of Regulation (EU) 2021/821 create regulatory risk for sovereign infrastructure vendors?
The full evaluation is expected to address AI model weights, quantum-computing components and cyber-surveillance software more explicitly. Vendors who have built product roadmaps on current decontrol exceptions, particularly for open-source AI, face the risk that new control entries could require licensing for transfers that are currently unrestricted. Proactive engagement with the EU Dual-Use Coordination Group and participation in public consultation phases reduces that risk.
Can PQC-capable HSMs sourced from US or Chinese manufacturers create GDPR transfer problems in addition to export-control issues?
Yes, on two separate legal bases. Under GDPR, if the HSM manufacturer or its parent is subject to US FISA 702 or Chinese National Intelligence Law obligations, any remote management, firmware update or telemetry channel could constitute a restricted international transfer under GDPR Chapter V. Simultaneously, the hardware may be subject to EAR controls that restrict re-export without BIS authorisation. Procurement contracts should require the vendor to confirm the exact ECCN classification of the HSM, whether any US-person involvement triggers ITAR, and a binding undertaking that no personal data is processed outside the EU in any support or maintenance activity.
Hoe Qsentinel dit oplost
Qsentinel is the managed Nextcloud Enterprise workspace, enhanced by Qsentinel with post-quantum encryption and sovereign private AI, hosted in Switzerland or on-premise, out of reach of the CLOUD Act.
